Vulnerabilities

Summary — last 7 days

New vulnerabilities2,765▼ 50 vs. last week
Critical / high1,432▲ 200 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)95▼ 405 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)0.60%—Actionpack Project ActionpackRubyonrails Rails2/9/20236/17/2026
An open redirect vulnerability is fixed in Rails 7.0.4.1 with the new protection against open redirects from calling redirect_to with untrusted user input. In prior versions the developer was fully responsible for only providing trusted input. However the check introduced could allow an attacker to bypass with a…
ModifiedMedium (6.1)1.6%—Rubyonrails ActionpackDebian Linux5/26/20226/17/2026
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
ModifiedMedium (6.1)1.8%—Rubyonrails ActionpackDebian Linux5/26/20226/17/2026
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
ModifiedHigh (7.5)4.1%—Rubyonrails RailsRubyonrails Actionpack Page-cachingDebian Linux5/27/20216/17/2026
A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.
ModifiedCritical (9.8)5.4%—Rubyonrails Actionpack Page-cachingDebian Linux5/12/20206/17/2026
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.